300-715 · Question #33
Which of the following is not true about profiling in Cisco ISE?
The correct answer is D. Cisco ISE does not support hierarchy within the profiling policy. Cisco ISE's profiling policies support a hierarchical structure, allowing for logical organization and inheritance of attributes, contrary to the statement that it does not.
Question
Which of the following is not true about profiling in Cisco ISE?
Options
- AProfiling policies are automatically enabled for use.
- BCisco ISE comes with predefined profiles.
- CThe use of Identity Groups is required to leverage the use of profiling in the authorization policy.
- DCisco ISE does not support hierarchy within the profiling policy.
How the community answered
(37 responses)- B3% (1)
- C3% (1)
- D95% (35)
Why each option
Cisco ISE's profiling policies support a hierarchical structure, allowing for logical organization and inheritance of attributes, contrary to the statement that it does not.
Profiling policies are automatically enabled for use once they are created or updated, ensuring immediate application of profiling rules.
Cisco ISE ships with a comprehensive set of predefined endpoint profiles that classify common device types, streamlining initial deployment and providing a baseline.
Identity Groups are essential for organizing endpoints based on their profile and are frequently used in authorization policies to grant appropriate access and enforce policy based on device type.
Cisco ISE profiling policies support a hierarchical structure, allowing for the creation of parent and child profiles where child profiles can inherit attributes from parent profiles and refine classifications, making the statement that it does not support hierarchy incorrect.
Concept tested: Cisco ISE Profiling Policy features
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ISE_admin_3_1/m_profiling.html
Topics
Community Discussion
No community discussion yet for this question.